Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 425/436
4.3
CVE-2026-63640

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, when hideConfigSecrets is enabled, the ca

4.3
CVE-2026-71322

Lemur manages TLS certificate creation. Prior to 1.9.3, CertificateExport placed its CertificatePermission ownership che

4.3
CVE-2026-76032

Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user. The REST handler for GET /a/share/

4.3
CVE-2026-70683

Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support

4.3
CVE-2026-71124

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authorization Engine). Suppo

4.3
CVE-2026-76041

Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to potentially bypass web or

4.3
CVE-2026-62289

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF or AVIF file containin

4.3
CVE-2026-62377

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by h

4.3
CVE-2025-11729

The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized acc

4.3
CVE-2026-14196

The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a review before allow

4.3
CVE-2026-16979

The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on tw

4.3
CVE-2026-19416

The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appointment being modified

4.3
CVE-2026-76166

A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single crafted UDP multica

4.3
CVE-2026-76209

phpMyFAQ versions before v4.1.6 fail to validate the security.enableRegistration setting in API endpoints, allowing atta

4.3
CVE-2026-76211

phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT permission on admin API read endpoints for LDAP, Elas

4.3
CVE-2026-40509

OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer. The web_path GET parameter

4.3
CVE-2026-76614

OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function. The archrestore_sel PO

4.3
CVE-2026-55703

Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id}

4.3
CVE-2026-16849

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an impro

4.3
CVE-2026-16886

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-o

4.3
CVE-2026-54492

Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createPodcastChannel.view

4.3
CVE-2026-76576

A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. This impacts the function fileDownload/resourceDownloa

4.3
CVE-2026-76256

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9,

4.3
CVE-2026-76309

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that does not hold the "ad

4.3
CVE-2026-76360

In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could use the /rest/health endpoint to

4.3
CVE-2026-76370

In Splunk SOAR versions below 8.6.0, an authenticated user with restricted tenant access could use the Representational

4.3
CVE-2026-76374

In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could

4.3
CVE-2026-76376

In versions below 2.1.9 of the AWS IAM app for Splunk SOAR, a user who holds a role with permission to run actions could

4.3
CVE-2026-76377

In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with permission to run action

4.3
CVE-2026-76378

In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who holds a role with permissi

4.3
CVE-2026-76379

In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with permission to run actions c

4.3
CVE-2026-76380

In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run

4.3
CVE-2026-76381

In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a role with permissio

4.3
CVE-2026-76382

In versions below 3.8.5 of the Phantom app for Splunk SOAR, a user who holds a role with permission to run actions could

4.3
CVE-2026-76383

In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with perm

4.3
CVE-2026-76384

In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds a role with permission

4.3
CVE-2026-76385

In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with permission to run actions could

4.3
CVE-2026-76386

In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to run actions could ex

4.3
CVE-2026-76398

In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the

4.3
CVE-2026-76405

In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" S

4.3
CVE-2026-14953

A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges

4.3
CVE-2026-73196

A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversize

4.3
CVE-2026-63015

Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons can view template inf

4.3
CVE-2026-53584

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing

4.3
CVE-2026-61663

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0

4.3
CVE-2026-64777

A malicious builder peer may be able to request an in-context file by name from the host and receive the contents of wha

4.3
CVE-2026-62945

TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions accept attacker-contr

4.3
CVE-2026-20679

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Ta

4.3
CVE-2026-77391

A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This a

4.3
CVE-2026-65645

Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP metho

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started